CVS Health

Distinguished Engineer - Application Security

CVS Health$175K — $334K *
US-AnywhereRemote in Arizona, US
Healthcare
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • 15+ years in technical roles influencing cross-functional teams
  • 10+ years bridging technical work with business strategies
  • 10+ years hands-on coding in multiple languages (Java, Python, etc.)
  • 8+ years in application security at enterprise scale
  • 5+ years defining technical strategy for DevSecOps programs
  • Expertise in modern application security tools
  • Experience integrating security into developer workflows

Responsibilities

  • Lead architectural direction for securing applications across platforms
  • Develop and implement a comprehensive application security program
  • Manage application security tooling stack and its integration
  • Provide technical leadership and hands-on support for security standards
  • Chart strategy for integrating AI in application development
  • Collaborate with Developer Experience for secure coding practices
  • Bridge communication between technical teams and business stakeholders

Benefits

  • Medical, dental, and vision coverage
  • Paid time off
  • Retirement savings options
  • Wellness programs
  • Resources supporting physical, emotional, and financial well-being
Full Job Description
Position Summary

Serves as the senior technical leader and strategist for Application Security at CVS Health, setting the architectural direction for how the enterprise secures the software that it builds and integrates across web, mobile, API, microservice, and AI-native applications spanning cloud, on-prem, SaaS and hybrid environments. Partners with the AVP, Application Security to define and deliver an industry-leading application security program that shifts security responsibility left into design and development, enforces it consistently through CI/CD, and validates it continuously in production, replacing point-in-time scan-and-triage workflows with a developer-native, control-driven, threat-informed model.

Owns the technical strategy and end-to-end architecture of the application security tooling stack including SAST, DAST, SCA, IAST/RASP, secrets scanning, API security, IaC and container scanning, ASPM/ASOC and its integration into the Developer Experience platform and enterprise CI/CD pipelines, so that security controls are consumed as native platform capabilities by application teams rather than as separate bolt-on tools. Accountable for tool selection, evaluation, and integration planning across a rapidly evolving vendor landscape, including build-vs-buy decisions and consolidation into a coherent Application Security Posture Management (ASPM) view. Serves as the ultimately responsible architect for the components, tools, and services developed and operated by the Application Security team, including microservices that integrate AppSec tools into CI/CD, reusable components, setting design standards, leading design reviews, and contributing hands-on to critical components. Provides hands-on support to application teams adopting standards and tooling, ensuring that the secure path is also the easy and default path.

Charts the enterprise course through the rapidly evolving field of AI-assisted software development, establishing the technical strategy and guardrails for safe adoption of AI coding assistants, agentic coding tools, and AI-generated code across the engineering organization; evaluating and integrating AI-native application security tooling (AI-assisted triage, autofix, secure code review, threat modeling, and detection engineering); and helping the enterprise navigate emerging risks including insecure generated code, prompt injection in developer workflows, model and prompt supply-chain exposure, and IP/data leakage through AI tooling.

Partners with the Developer Experience team to design and deliver the developer-facing side of the program, secure-by-default paved paths, secure coding standards mapped to OWASP ASVS and NIST SSDF, and outcome-based metrics that translate application security posture into business risk. Partners closely with the Developer Experience team that manages the enterprise CI/CD pipelines, and with Security Engineering peers across Cloud Security, AI Security, Identity, Detection Engineering, and Exposure Management, to ensure application security controls are integrated end-to-end from developer laptop to production runtime. Operates as a trusted bridge between deeply technical engineering teams and business stakeholders, influencing strategy, investment, and execution across organizational boundaries without relying on direct authority.

This role can be remote anywhere in the continental USA.

Required Qualifications
  • 15+ years of experience in technical roles, with demonstrated ability to influence without authority across technical and executive audiences
  • 10+ years of experience acting as a bridge between deep technical work and business strategy, translating between the two fluently
  • 10+ years of hands-on software engineering experience across multiple language ecosystems (e.g., Java, C#, JavaScript/TypeScript, Python, Go) - with recent, current coding proficiency, not solely architectural or advisory experience
  • 8+ years in application security or product security roles at enterprise scale, including hands-on experience with threat modeling, secure design review, secure code review, and vulnerability triage
  • 5+ years setting multi-year technical strategy and architectural roadmaps for enterprise-scale application security or DevSecOps programs
  • Deep working knowledge of the modern application security tooling landscape - SAST, DAST, SCA, IAST/RASP, secrets scanning, API security, container and IaC scanning, ASPM/ASOC - including hands-on experience selecting, integrating, tuning, and operating these tools at enterprise scale
  • Demonstrated experience integrating security controls into modern CI/CD pipelines and developer platforms (Git-based workflows, GitHub Actions / GitLab CI / Jenkins / Argo, container registries, artifact repositories, service catalogs) as native, low-friction platform capabilities
  • Strong working knowledge of software supply chain security - SBOMs (CycloneDX, SPDX), the SLSA framework, provenance and attestation, dependency and license governance, and build-system hardening
  • Deep familiarity with cloud-native architectures (Kubernetes, serverless, microservices), API design patterns (REST, GraphQL, gRPC, event-driven), and the security implications of each
  • Demonstrated experience leading the transformation of an application security program from centralized, gate-oriented, meeting-driven workflows to developer-native, control-driven, continuous operations - including measurable improvements in adoption, remediation velocity, and defect escape rate
  • Demonstrated experience partnering with platform engineering or developer experience teams to deliver security capabilities as native platform features rather than external gates
  • Strong written and verbal communication, including proven experience briefing executive leadership and the board


Preferred Qualifications
  • Practical, current experience with AI-assisted software development - evaluating and governing AI coding assistants (e.g., Claude Code, GitHub Copilot, Cursor, Windsurf, Cody, Amazon Q Developer, and equivalents), agentic coding tools, and MCP-based developer integrations - including security guardrails and organizational rollout patterns
  • Hands-on experience evaluating and integrating AI-native application security tooling - AI-assisted triage, autofix, secure code review, and AI threat modeling capabilities - with practical awareness of accuracy, false-positive, and prompt-injection concerns
  • Deep working knowledge of OWASP LLM Top 10, OWASP AI Security & Privacy Guide, MITRE ATLAS, and NIST AI RMF as they apply to application security
  • Experience with Application Security Posture Management (ASPM) platforms and unified security signal aggregation, correlation, and prioritization across the AppSec toolchain
  • Healthcare-sector application security experience: PHI-handling clinical and pharmacy systems, HIPAA Security Rule, FDA pre-market and post-market cybersecurity guidance (including SPDF), retail pharmacy PCI-scoped applications, and clinical-system safety considerations
  • Experience operating application security programs simultaneously against HIPAA, HITRUST CSF, PCI DSS 4.0, the SEC cyber-incident disclosure rule, and NIST CSF 2.0
  • Experience with runtime application security capabilities - RASP, eBPF-based runtime protection, service mesh security, and WAF/API gateway integration - and with correlating runtime signals back to source code and design
  • Experience partnering with product management, engineering leadership, and platform engineering to embed security into developer workflows without slowing delivery velocity
  • Experience influencing standards bodies, open-source projects, or industry working groups relevant to application security or secure software development
  • Industry certifications such as CISSP, CSSLP, OSWE, OSCP, GIAC (e.g., GWEB, GWAPT, GMOB, GCSA), or equivalent
  • Advanced degree in Computer Science, Software Engineering, or related technical field
  • Open-source, publication, or community contribution in application security, DevSecOps, secure software development, or AI-assisted development
  • Advanced degree in Computer Science

Education

Bachelor's degree in Computer Science, Engineering, or a related field.

Pay Range

The typical pay range for this role is:

$175,100.00 - $334,750.00

This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company's equity award program.

Great benefits for great people

We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.

This full-time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well-being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.

Additional details about available benefits are provided during the application process and on Benefits Moments.

We anticipate the application window for this opening will close on: 12/31/2026

About CVS Health

Omnicare provides comprehensive pharmaceutical services to patients and providers across the United States. As the market-leader in professional pharmacy, related consulting and data management services for skilled nursing, assisted living and other chronic care settings, Omnicare leverages its unparalleled clinical insight into the geriatric market along with some of the industry's most innovative technological capabilities to the benefit of its long-term care customers. Omnicare also provides key commercialization services for the bio-pharmaceutical industry through its Specialty Care Group.

CVS Health Careers

Joining CVS Health presents a unique opportunity to advance your career in a company where innovation, leadership, and growth go hand in hand. As a leader in the healthcare industry, CVS Health is more than just a pharmacy. We are a team of professionals dedicated to improving lives and optimizing health outcomes.

Work You’ll Do

At CVS Health, you will be part of a culture that values diversity and inclusivity, fostering an environment where every team member’s contribution is valued. Engage in meaningful work that directly impacts lives, driving innovation in healthcare services and solutions.

Explore Job Opportunities

Whether you’re looking for a position in pharmacy services, corporate leadership, or in-store management, CVS Health offers a variety of employment opportunities that will help you harness your skills and thrive professionally. Our job opportunities span across a wide range of professional fields and geographic locations, ensuring that your career at CVS Health aligns with your professional goals and lifestyle.

Internship Programs

Kickstart your career with CVS Health through our internship programs. These opportunities are designed for ambitious students eager to develop their skills in a real-world setting. Internships at CVS Health are not only about gaining work experience but also about making meaningful contributions to our ongoing projects.

Professional Growth and Development

CVS Health is committed to the professional growth of our employees. With access to cutting-edge technology, industry-leading experts, and comprehensive diversity training, our team members are equipped to lead and innovate. We support career advancement through professional development programs, leadership training, and opportunities for networking and internal mobility.

Benefits and Culture

Our employees enjoy a range of benefits that reflect our commitment to their well-being and success. From health and wellness benefits to professional development programs, CVS Health is dedicated to ensuring our team members have the resources they need. Our inclusive culture encourages collaboration and continuous learning, making CVS Health a place where you can grow and succeed.

Join Our Team

Ready to take the next step in your career? Explore the open positions at CVS Health that match your skills and interests. We are continuously hiring and looking for passionate, curious, and solution-driven team players.

Stay Connected

Keep up to date with the latest news, career tips, and industry insights from CVS Health. Personalize your experience by subscribing to job alert emails, tailored to your preferences and professional interests. Discover the rewarding opportunities that await at CVS Health, where your career development is always a priority.

Search CVS Health Jobs

Don’t just look for a job. Look for a place where you can be a part of something bigger. Visit our careers page to find the position that’s right for you and join a team that values innovation and leadership in healthcare.

READ CAREERS BLOG

Stay ahead in your career with insights from those who know CVS Health best – our team. Learn from their experiences and get insider tips that can help you succeed in your next interview, craft a standout resume, and build a career you’re proud of at CVS Health.
Learn more about CVS Health
Size
300,000 employees
Market Cap
$122 billion
Industry
Net Income
$7.1 billion
Founded
1963
5 Year Trend
+10.5%
Revenue
$268.7 billion
NASDAQ

Similar Jobs

More Jobs at CVS Health

More Healthcare Jobs

Find similar Distinguished Engineer - Application Security jobs: